Skip to main content

Engine Pack Version 9.6.7

CxSAST Engine

Languages & Frameworks

The Supported Code Languages and Frameworks lists all supported versions of code languages and frameworks.

Rust

The Rust support has been improved by adding additional queries and is now GA.

The following queries are available as part of this version:

  • High_Severity.png:High_Risk: Rust_High_Risk

    • DynamoDB_NoSQL_Injection

    • AWS_Credentials_Leak

  • Medium_Severity.png:Medium_Risk: Rust_Medium_Threat

    • Excessive_Data_Exposure

    • External_Control_of_System_or_Config_Setting

    • Hardcoded_AWS_Credentials

    • Improper_Locking

    • PCI_Data_Exposure_in_JWT

    • Secret_Leak_in_JWT

    • Use_of_Native_Language

  • Low_Severity.png:Low_Risk: Rust_Low_Visibility

    • Compromised_CDN

    • Dangerous_File_Extension

    • Heap_Inspection

    • Improper_Resource_Shutdown_or_Release

    • Incorrect_Permission_Assignment_For_Critical_Resources

    • Off_By_One_Error

    • Race_Condition_In_Cross_Functionality

    • Serializable_Class_Containing_Sensitive_Data

    • sage_of_temp_dir

CSharp

CSharp support was updated to version 12.

.NET

.NET support was updated to version 8.

RPG

The RPG Resolver performance was improved. As for the language, Prototypes are now represented as Method Signatures.

Presets

ASA Premium

The ASA Premium preset has been updated to include additional Rust queries.

CWE Top 25

The CWE Top 25 preset and its corresponding category have been updated to support version 2023.

Critical Severity

Critical severity will be added to the SAST engine's list of severity options in the upcoming major version, 9.7.0.

Queries

To include the Critical severity, all queries will be revised and their severity adjusted accordingly.

Details on the affected queries can be found on page Queries Severity Revision .Queries Severity Revision

Presets
  • No new presets will be created or renamed.

  • The following presets will be updated:

    • High, Medium, and Low

      • Queries reviewed from High/Medium/Low to Critical are being kept on this preset.

      • Queries classified from High/Medium/Low to Info are being removed from this preset.

      • All other queries that are transitioning between High, Medium, and Low severities are kept in the preset

        (Example: a query reclassified from High to Medium or Low to Medium will be kept in the preset).

    • High and Medium

      • Queries reviewed from High/Medium to Critical are being kept on this preset.

      • Queries reviewed from Low to Critical/High/Medium are being added to the preset.

      • Queries reviewed from High/Medium to Low/Info are being removed.

      • All other queries that are transitioning between High and Medium severities are kept in the preset

        (Example: a query reviewed from Medium to High is kept in the preset).

  • No queries have been added or removed for all other presets. The only changes are reclassifications of query severities, as detailed in the URL above: Queries Severity Revision.Queries Severity Revision

Scans & Results

New severity will be reflected only for new scans executed after upgrading to 9.7.0; older scans and results are unaffected.

Engine Pack Supported Code Languages and Frameworks (9.6.7)

Environment and Primary Languages

Secondary Languages

Framework

File extensions

Additional Information

6022007568
  • Java

  • J2SE

  • J2EE

  • JSP

  • JavaScript

  • VBScript

  • PL\SQL

  • HTML5

  • ATG DSP Taglib

  • GWT

  • Hibernate

  • Google Guice

  • Java Server Faces (JSF)

  • JSP

  • JSTL FMT Taglib

  • OWASP ESAPI

  • MyBatis

  • PrimeFaces

  • Spring Boot

  • Spring MVC

  • Spring

  • Struts

  • Velocity

  • .java

  • .jsp

  • .jspf

  • .jsf

  • .tag

  • .tld

  • .mf

  • .xhtml

  • .vm

  • .gradle

  • .properties

  • .jspdsbld

  • .wod

  • .xml

  • .yml

  • .yaml

Java can be configured as a unified language with Scala.

6022007571.png
  • ASP.NET

  • JavaScript

  • VBScript

  • PL\SQL

  • HTML5

  • ASP.NET Core

  • ASP.Net Core Razor

  • ASP.Net MVC framework

  • Enterprise Libraries

  • ComponentArt

  • Entity framework

  • Hibernate.Net

  • Infragistics

  • iBatis

  • Telerik

  • Dapper

  • .Net Core

  • .Net Framework

  • .NET

  • .cs

  • .cshtml

  • .xaml

  • .vb

  • .config

  • .aspx

  • .ascx

  • .asax

  • .tag

  • .master

  • .xml

6022007574.png
  • ASP

  • JavaScript [**]

  • VBScript

  • PL\SQL

  • HTML5

  • ASP.Net MVC framework

  • .asp

  • .inc

6022007577.png
  • VB6

  • .bas

  • .vbp

  • .frm

  • .cls

  • .dsr

  • .ctl

6022007580.png
  • C

  • C++

  • C MISRA

  • C++ MISRA

  • Informix ESQL/C

  • MySQL

  • .cpp

  • .c

  • .cc

  • .c++

  • .cxx

  • .hpp

  • .hh

  • .h++

  • .hxx

  • .h

  • .ec

  • .cmake

  • .pc

  • .pro

  • .ac

  • .am

  • .txt (related to CmakeLists)

  • .ph

64d4d824681bd.svg
  • PHP

JavaScript

  • bWapp

  • CakePHP

  • OWASP ESAPI

  • Kohana

  • Symfony

  • Smarty

  • Zend

  • .php

  • .php3

  • .php4

  • .php5

  • .phtm

  • .phtml

  • .tpl

  • .ctp

  • .twig

  • .inc

  • .cgi

  • .env

  • .ini

6022007586.png
  • Apex

  • VisualForce

  • Lightning (Aura)

  • Lightning Web Components

  • .apex

  • .apexp

  • .apxc

  • .page

  • .component

  • .cls

  • .trigger

  • .tgr

  • .object

  • .report

  • .workflow

  • -meta.xml

  • .xml

This is for Salesforce APEX only.

6022007589.png
  • Ruby

  • Ruby on Rails

  • .rb

  • .rhtml

  • .rxml

  • .rjs

  • .erb

  • .cgi

  • .lock

6022007592.png
  • JavaScript

  • Typescript

  • Ajax

  • Angular

  • AngularJS

  • Backbone

  • Cordova / PhoneGap

  • Handlebars

  • Hapi.JS

  • JQuery

  • Knockout

  • Kony Visualizer

  • Node.js

    • Buffer

    • CryptoJS

    • ExpressJS

    • File System

    • Hapi

    • Mongodb

    • OracleDB

    • Sequelize

  • Pug (Jade)

  • React Native

  • ReactJS

  • SAPUI5

  • VueJS

  • XS (SAP)

  • RequireJS

  • .js

  • .jsx

  • .htm

  • .html

  • .json

  • .ts

  • .tsx

  • .aspx

  • .ascx

  • .xsjs

  • .xsjslib

  • .xsaccess

  • .xsapp

  • .app

  • .evt

  • .cmp

  • .hbs

  • .handlebars

  • .jade

  • .pug

  • .vue

  • .xml

  • .apexp

  • .page

  • .component

  • .cshtml

  • .jsf

  • .xhtml

  • .jsp

  • .jspf

  • .asp

  • .master

  • .php

6022007598.png
  • VBScript

  • .vbs

  • .aspx

  • .ascx

  • .asp

  • .cshtml

  • .html

  • .htm

  • .master

6022007601.png
  • Perl

  • .pl

  • .pm

  • .plx

  • .psgi

  • .cgi

6022007604.png
  • Android (Java)

  • Volley

  • .java

  • .kt

6022007607.png
  • Objective-C

  • Swift

  • .m

  • .h

  • .swift

  • .xib

  • .plist

6022007610.png
  • HTML 5

  • .html

  • .htm

6022007613.png
  • PL/SQL

  • .pls

  • .sql

  • .pkh

  • .pks

  • .pkb

  • .pck

6022007616.png
  • Python

  • JavaScript

  • VB script

  • PL\SQL

  • Django

  • Flask

  • Jinja and DTL

  • Pandas library

  • Marshmallow

  • .py

  • .gtl

  • .csv

  • .latex

  • .tex

  • .html

  • .xml

  • .txt

6022007619.png
  • Groovy

  • JavaScript

  • VB script

  • PL\SQL

  • .groovy

  • .gsh

  • .gvy

  • .gy

  • .gsp

  • .gradle

6022007622.png
  • Scala

  • Akka

  • Finagle

  • Finatra

  • .scala

  • .conf

Scala can be configured as a unified language with Java.

6022007625.png
  • GO Language

  • Protobuf

  • gin-gonic/gin

  • gorilla-mux

  • .go

  • .mod

kotlinlogo.png
  • Kotlin

  • Ktor (Server Side)

  • Vert.x (Server Side)

  • Spring

  • .kt

  • .kts

  • .mustache

  • .ftl

  • .xml

6022007508.jpg
  • Cobol

  • .cbl

  • .cob

  • .eco

  • .pco

  • .sqb

  • .cpy

6994002109.png
  • RPG

  • .rpg

  • .rpg38

  • .sqlrpg

  • .rpgle

  • .sqlrpgle

  • .dspf

6994002106.png
  • Dart

  • Flutter

  • .dart

  • .yaml

6993019381.png
  • Lua

  • OpenResty

  • .lua

  • .conf

Rust.png
  • Rust

  • .rs

Vulnerability Queries 9.6.7

All queries that are executed in version 9.6.7 are available for download  - PDFCSV

New and updated queries in version 9.6.7 are available for download - PDFCSV

Queries associated with predefined query presets are available for download - PDFCSV

New and Changed Queries Details - PDF